Fun

Alex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiK

News Feed - 2024-05-15 05:05:19

Christopher Roark3 hours agoAlex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiKThe deployer account changed an Alex contract’s implementation address, and multiple tokens were subsequently drained from its bridge.887 Total views9 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAccording to a May 14 report from blockchain security platform CertiK, the Alex protocol bridge on the BNB Smart Chain network suffered $4.3 million in suspicious withdrawals just after its contract was suddenly upgraded.


Alex is a Bitcoin layer-2 protocol. According to its official website, it provides decentralized finance applications on Bitcoin. Its bridges are used to transfer assets from other networks, such as BNB Smart Chain and Ethereum, to its own network.


Blockchain data confirms that the Alex deployer account performed five identical upgrades to the “Bridge Endpoint” contract on BNB Smart Chain beginning at 3:56 pm UTC. Approximately $4.3 million worth of Binance-Pegged Bitcoin (BTC), USD Coin (USDC), and Sugar Kingdom Odyssey (SKO) were subsequently removed from the BNB Smart Chain side of the bridge.


Because the upgrade was performed by the protocol’s deployer account, CertiK labeled the event “a possible private key compromise.” Source: CertiK


The upgrade transaction changed the implementation address to one ending in 7058. The new implementation is unverified bytecode, making it unreadable to human beings.


About 48 minutes after these upgrades began, the proxy address for the bridge contract called an unverified function on an address ending in 4848E. This resulted in 16 BTC ($983,000 at current prices), 2.7 million SKO ($75,000) and $3.3 million worth of USDC at 4:44 pm, being moved into the address at 484E.


The attacker may also be attempting to drain funds on other networks. At 5:41 pm, just minutes after the suspicious upgrade on BNB Smart Chain, a similar series of Alex upgrades occurred on Ethereum. In this case, the deployer upgraded the “artist address” to an unverified contract. Immediately afterward, an account ending in 05ed attempted to make two withdrawals from the “team address.” These withdrawals failed, producing a “not owner” error.


The 05ed account had no history before May 10. It created one unverified contract on May 10 and two more on May 14, indicating that it may be under the control of a malicious user.


At the time of publication, the Alex team has not confirmed the exploit or commented on the incident.


The Alex bridge wasn’t the only protocol to face a potential exploit in May. On May 13, decentralized exchange Equalizer announced that it had lost more than 2,000 of its own tokens from an attacker who siphoned them away in small increments over several days. The Gnus.ai hack on May 6 also resulted in $1.27 million worth of losses.


Related:CertiK discovered $5M security flaw in Wormhole bridge on Aptos# Bitcoin# Blockchain# Ethereum# Hackers# Private Keys# Cybersecurity# Hacks# DeFi# Layer2Add reaction

News Feed

Fidelity Digital Assets Touts Bitcoin Credentials, As Publicly Traded Companies Now Hold Over 600,000 BTC
Fidelity Digital Assets Touts Bitcoin Credentials, As Publicly Traded Companies Now Hold Over 600,000 BTC Fidelity Digital Assets (FDA) says diversifying an inve
Amaka Nwaokocha1 hour agoNigeria’s Web3 education efforts seek to tackle language challengesBello Usman Abdullahi, the chief operating officer of the blockchain education platform Bitkova Academy, said the language bar
1.2 Million Italians Can Now Buy Bitcoin From Their Bank
1.2 Million Italians Can Now Buy Bitcoin From Their Bank Buying bitcoin just got easier for Italians. The country’s mobile bank Hype has announced a partnership with fintec
GBTC outflows top $358M, but one theory suggests it’s almost over
Tom Mitchelhill3 hours agoGBTC outflows top $358M, but one theory suggests it’s almost overIt’s been another big day of outflows from Grayscale’s Bitcoin ETF, but ETF analyst Eric Balchunas believes they will taper
Declining ETH Gas Cost Still Higher Than BTC Fees: Supporters Insists ETH 2.0 to End High Fee Woe
Declining ETH Gas Cost Still Higher Than BTC Fees: Supporters Insists ETH 2.0 to End High Fee WoeEthereum network gas fees that averaged $15.13 on September 2 have been declining in
Adidas Steps Into the Metaverse by Partnering With NFT Projects Bored Ape Yacht Club, Punks Comic
Adidas Steps Into the Metaverse by Partnering With NFT Projects Bored Ape Yacht Club, Punks Comic The German multinational corporation that crafts athletic shoes, sportswear, and a
Yield App Doubles Assets In Q3 As It Scores Big With Premier League Partnership
Yield App Doubles Assets In Q3 As It Scores Big With Premier League Partnership sponsored YIELD App, a FinTech company and digital asset wealth management platform, has published it
BitMart Lists BEP2 Token – Agora VOTE
TwitterFacebookLinkedInReddit BitMart, a premier global digital asset trading platform, recently announced the listi
Electricity Consumption of Russian Crypto Miners Spikes 20 Times in 5 Years, Research Finds
Electricity Consumption of Russian Crypto Miners Spikes 20 Times in 5 Years, Research Finds Power needs of cryptocurrency miners in Russia have grown significantly since 2017, with
Bank of France Governor Calls for Mandatory Licensing for Crypto Companies
Bank of France Governor Calls for Mandatory Licensing for Crypto Companies France has to adopt a licensing regime for crypto service providers, the head of the country’s central
‘Midnight Massacre:’ SEC Crackdown on Crypto Staking Services Prompts Speculation of Further Enforcement Actions
‘Midnight Massacre:’ SEC Crackdown on Crypto Staking Services Prompts Speculation of Further Enforcement Actions On Feb. 9, 2023, the cryptocurrency community learned of the U.
Ethereum Classic Hashrate Slides 46% Since The Merge, PoW ETH Forks Gather Double-Digit Gains
Ethereum Classic Hashrate Slides 46% Since The Merge, PoW ETH Forks Gather Double-Digit Gains The day of The Merge, Ethereum Classic’s hashrate soared to new highs tapping 3